CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,553 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
170,396 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-0285 EXP | Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1… | Patch early | 5.0 medium | 3% | 2017-06-15 |
| CVE-2017-0286 EXP | Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 16… | Patch early | 5.0 medium | 3% | 2017-06-15 |
| CVE-2017-0288 EXP | Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 16… | Patch early | 5.0 medium | 3% | 2017-06-15 |
| CVE-2006-4884 EXP | Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary web script or HTML via (1) the… | Patch early | 4.3 medium | 3% | 2006-09-19 |
| CVE-2003-0481 EXP | Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated using the msg… | Patch early | 4.3 medium | 3% | 2003-08-07 |
| CVE-2008-5770 EXP | Cross-site scripting (XSS) vulnerability in config/make_config.php in PHP Weather 2.2.2 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3% | 2008-12-30 |
| CVE-2004-2487 EXP | Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..",… | Patch early | 4.0 medium | 3% | 2004-12-31 |
| CVE-2008-0218 EXP | Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail Server allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 3% | 2008-01-10 |
| CVE-2009-3666 EXP | Cross-site scripting (XSS) vulnerability in index.php in Nullam Blog 0.1.2 allows remote attackers to inject arbitrary web script or HTML via the e pa… | Patch early | 4.3 medium | 3% | 2009-10-11 |
| CVE-2010-3462 EXP | Cross-site scripting (XSS) vulnerability in backend/plugin/Registration/index.php in Mollify 1.6, 1.6.5.5, and possibly other versions allows remote a… | Patch early | 4.3 medium | 3% | 2010-09-17 |
| CVE-2006-1581 EXP | Directory traversal vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the _path par… | Patch early | 6.4 medium | 3% | 2006-04-02 |
| CVE-2006-1821 EXP | Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing… | Patch early | 6.4 medium | 3% | 2006-04-18 |
| CVE-2005-4074 EXP | Directory traversal vulnerability in index.cfm in CF_Nuke 4.6 and earlier, when Sandbox Security is disabled, allows remote attackers to include arbit… | Patch early | 5.0 medium | 3% | 2005-12-08 |
| CVE-2000-0453 EXP | XFree86 3.3.x and 4.0 allows a user to cause a denial of service via a negative counter value in a malformed TCP packet that is sent to port 6000. | Patch early | 5.0 medium | 3% | 2000-05-18 |
| CVE-2004-0616 EXP | The BT Voyager 2000 Wireless ADSL Router has a default public SNMP community name, which allows remote attackers to obtain sensitive information such… | Patch early | 5.0 medium | 3% | 2004-12-06 |
| CVE-2008-2032 EXP | The FTP service in Acritum Femitter Server 1.03 allows remote attackers to cause a denial of service (crash) by sending multiple crafted RETR commands… | Patch early | 5.0 medium | 3% | 2008-04-30 |
| CVE-2008-4601 EXP | Cross-site scripting (XSS) vulnerability in the login feature in Habari CMS 0.5.1 allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 3% | 2008-10-18 |
| CVE-2010-2316 EXP | Multiple cross-site scripting (XSS) vulnerabilities in default.asp in WmsCms 2.0 and earlier allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 3% | 2010-06-17 |
| CVE-2000-0903 EXP | Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (… | Patch early | 5.0 medium | 3% | 2000-12-19 |
| CVE-2000-0914 EXP | OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests. | Patch early | 5.0 medium | 3% | 2000-12-19 |
| CVE-2001-0074 EXP | Directory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the board para… | Patch early | 5.0 medium | 3% | 2001-02-12 |
| CVE-2001-0306 EXP | Directory traversal vulnerability in ITAfrica WEBactive HTTP Server 1.00 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL. | Patch early | 5.0 medium | 3% | 2001-05-03 |
| CVE-2021-24719 EXP | The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions… | Patch early | 6.1 medium | 3% | 2021-10-11 |
| CVE-2009-0383 EXP | delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog posts via a direct request. | Patch early | 6.4 medium | 3% | 2009-02-02 |
| CVE-2008-2820 EXP | Directory traversal vulnerability in lang/lang-system.php in Open Azimyt CMS 0.22 minimal and 0.21 stable allows remote attackers to include and execu… | Patch early | 6.4 medium | 3% | 2008-06-23 |
| CVE-2006-3194 EXP | Directory traversal vulnerability in index.php in singapore 0.10.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) sequ… | Patch early | 6.4 medium | 3% | 2006-06-23 |
| CVE-2007-3555 EXP | Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expre… | Patch early | 4.3 medium | 3% | 2007-07-04 |
| CVE-2006-0725 EXP | PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote attackers to include arbitr… | Patch early | 6.8 medium | 2.9% | 2006-02-16 |
| CVE-2006-1022 EXP | PHP remote file include vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows remote attackers to… | Patch early | 5.0 medium | 2.9% | 2006-03-07 |
| CVE-2018-1002001 EXP | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileg… | Patch early | 4.8 medium | 2.9% | 2018-12-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt